How to get tidy updated in various distribution channels?

Geoff McLane <[email protected]> Mon, 28 Sep 2015 15:32:29 +0200
Newsgroups gmane.comp.web.html-tidy.user
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--------------070606030407000503040301
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit

Cross post this on the public list

-------- Forwarded Message --------
Subject: 	How to get tidy updated in various distribution channels?
Date: 	Mon, 28 Sep 2015 15:27:11 +0200
From: 	Geoff McLane <[email protected]>
To: 	Edward Vielmetti <[email protected]>, Sierk Bornemann 
<[email protected]>
CC: 	[email protected], Ryan Schmidt <[email protected]>



Hi Sierk,

As Edward points out, thanks largely to him, we have
the Apple platform well covered, but it would be nice
if Apple also weighed in ;=))

But there is a real problem with Ubuntu (Debian)! And
probably LOTS of other package distributions...

I just checked synaptic in my Ubuntu 14.04 LTS, and it
still lists libtidy-0.99, circa 2009 ;=(( YUK!!!

I checked around LaunchPad - https://launchpad.net/tidy -
and found this still points to sourceforge 2009 tidy,
home page and source! UGH!

How do we change that? I do not fully understand how
these things work, having not used them before...

But maybe we should write to Curtis Hovey (maybe
[email protected]?)? Direct approach... maybe cc
him on this...

Or maybe there is a way to file for a badly needed
package update??? Where?

And the page - https://launchpad.net/ubuntu/trusty/+source/tidy -
also shows 2009 Tidy, despite the fact that an update
(Ha!) was done 2015-07-23!!! Nearly a month after our
5.0.0 release...

We certainly need to STIR something up somewhere ;=))

Important Links:

     site: http://www.html-tidy.org/
     source: https://github.com/htacg/tidy-html5
     binaries: http://www.htacg.org/binaries/
     bugs: https://github.com/htacg/tidy-html5/issues
     list: https://lists.w3.org/Archives/Public/html-tidy/
     api: http://www.htacg.org/tidy-html5/tidylib_api/
     quickref: http://www.htacg.org/tidy-html5/quickref.html

Regards,
Geoff.


On 26/09/15 01:41, Edward Vielmetti wrote:
> Sierk - sure take my text and use it if it will help.
>
> My next desire is not so much for Apple to update tidy (since it's readily
> available in Macports and fink and Homebrew that platform is OK).
> But Debian has an ancient tidy and I think that's addressable
> in finite time to improve at least to get tidy-html5 into `sid`.
>
> On Fri, Sep 25, 2015 at 5:52 PM, Sierk Bornemann <[email protected] 
> <mailto:[email protected]>> wrote:
>
>     Hi Geoff,
>     hi Edward,
>     hi Ryan!
>
>     Tidy is part of Apple’s Open Source stack Darwin and so part of
>     their OS X distribution since years [1] as well as part of iOS as
>     well as of their newest OS, watchOS. Unfortunately, it's a very
>     old version:
>
>     OS X 10.10.5 (Yosemite)
>     $ tidy --version
>     HTML Tidy for Mac OS X released on 31 October 2006 - Apple Inc.
>     build 15.15
>
>     Latest security updates for iOS and watchOS contain updates for
>     tidy, concerning CVE-2015-5522 and CVE-2015-5523 vulnerabilities,
>     which are closed in Tidy 4.9.31 and later 5.x.
>
>     Apples Tidy is very outdated, is an old version based on the last
>     available version on SourceForge, hasn’t changed and updated for
>     years, isn’t capable of HTML5.
>     Years ago, Nov 17 2008, I filed a bug "Update HTML Tidy and
>     TidyLib to the latest official version" in Apple’s internal bug
>     database on https://bugreport.apple.com/ and mirrored the bug for
>     transparency purpose on OpenRadar [3]. I updated the bug’s
>     information July 31 2014, reflecting that W3C had forked the dead
>     SF tidy project to give it new life and to urge Apple to please
>     update tidy.
>     So far no reaction, no update from Apple to their tidy.
>     Since then, I’ve not updated the bug’s description, to reflect the
>     new situation under HTACG’s umbrella, but want do so shortly.
>
>     [1] http://www.opensource.apple.com/
>     http://www.opensource.apple.com/source/tidy/
>     http://www.apple.com/opensource/
>
>     [2] APPLE-SA-2015-09-16-1 iOS 9
>     http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html
>
>     tidy
>     Available for:  iPhone 4s and later,
>     iPod touch (5th generation) and later, iPad 2 and later
>     Impact:  Visiting a maliciously crafted website may lead to arbitrary
>     code execution
>     Description:  A memory corruption issue existed in Tidy. This issues
>     was addressed through improved memory handling.
>     CVE-ID
>     CVE-2015-5522 : Fernando Munoz of NULLGroup.com
>     CVE-2015-5523 : Fernando Munoz of NULLGroup.com
>
>     APPLE-SA-2015-09-21-1 watchOS 2
>     http://lists.apple.com/archives/security-announce/2015/Sep/msg00005.html
>
>     [quote]
>     tidy
>     Available for:  Apple Watch Sport, Apple Watch,
>     and Apple Watch Edition
>     Impact:  Visiting a maliciously crafted website may lead to arbitrary
>     code execution
>     Description:  A memory corruption issue existed in Tidy. This issues
>     was addressed through improved memory handling.
>     CVE-ID
>     CVE-2015-5522 : Fernando Munoz of NULLGroup.com
>     CVE-2015-5523 : Fernando Munoz of NULLGroup.com
>     [/quote]
>
>     [3] OpenRadar bug 6376494 (Apple internal rdar://6376494): Update
>     HTML Tidy and TidyLib to the latest official version
>     http://openradar.appspot.com/6376494
>
>
>
>     My question to you is: what can be done, what can you/we do,
>     beyond my past efforts in this case, to convince Apple to
>     eventually update its old outdated stock tidy to the most recent
>     stable one of HTACG? Any Idea? Any suggestions?
>
>     @Edward Vielmetti:
>     May I take, with your allowance, just for convenience and instead
>     of writing my own text, your text of fink ticket #1044
>     http://sourceforge.net/p/fink/package-requests/1044/ and copy it
>     for updating my Apple Rdar-bug 6376494 as well as its OpenRadar
>     equivalent?
>
>     Suggestions and help welcome,
>     Regards,
>     Sierk Bornemann
>
>     --
>     Sierk Bornemann | web developer | germany
>
> -- 
> Edward Vielmetti +1 734 330 2465
> [email protected] <mailto:[email protected]>
>




--------------070606030407000503040301
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 8bit

<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=utf-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    Cross post this on the public list<br>
    <div class="moz-forward-container"><br>
      -------- Forwarded Message --------
      <table class="moz-email-headers-table" border="0" cellpadding="0"
        cellspacing="0">
        <tbody>
          <tr>
            <th align="RIGHT" valign="BASELINE" nowrap="nowrap">Subject:
            </th>
            <td>How to get tidy updated in various distribution
              channels?</td>
          </tr>
          <tr>
            <th align="RIGHT" valign="BASELINE" nowrap="nowrap">Date: </th>
            <td>Mon, 28 Sep 2015 15:27:11 +0200</td>
          </tr>
          <tr>
            <th align="RIGHT" valign="BASELINE" nowrap="nowrap">From: </th>
            <td>Geoff McLane <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]">&lt;[email protected]&gt;</a></td>
          </tr>
          <tr>
            <th align="RIGHT" valign="BASELINE" nowrap="nowrap">To: </th>
            <td>Edward Vielmetti <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]">&lt;[email protected]&gt;</a>,
              Sierk Bornemann <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]">&lt;[email protected]&gt;</a></td>
          </tr>
          <tr>
            <th align="RIGHT" valign="BASELINE" nowrap="nowrap">CC: </th>
            <td><a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>, Ryan Schmidt
              <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]">&lt;[email protected]&gt;</a></td>
          </tr>
        </tbody>
      </table>
      <br>
      <br>
      <meta content="text/html; charset=utf-8" http-equiv="Content-Type">
      Hi Sierk,<br>
      <br>
      As Edward points out, thanks largely to him, we have <br>
      the Apple platform well covered, but it would be nice <br>
      if Apple also weighed in ;=))<br>
      <br>
      But there is a real problem with Ubuntu (Debian)! And <br>
      probably LOTS of other package distributions...<br>
      <br>
      I just checked synaptic in my Ubuntu 14.04 LTS, and it <br>
      still lists libtidy-0.99, circa 2009 ;=(( YUK!!!<br>
      <br>
      I checked around LaunchPad - <a moz-do-not-send="true"
        class="moz-txt-link-freetext" href="https://launchpad.net/tidy">https://launchpad.net/tidy</a>
      - <br>
      and found this still points to sourceforge 2009 tidy, <br>
      home page and source! UGH!<br>
      <br>
      How do we change that? I do not fully understand how <br>
      these things work, having not used them before...<br>
      <br>
      But maybe we should write to Curtis Hovey (maybe <br>
      <a moz-do-not-send="true" class="moz-txt-link-abbreviated"
        href="mailto:[email protected]">[email protected]</a>?)?
      Direct approach... maybe cc <br>
      him on this...<br>
      <br>
      Or maybe there is a way to file for a badly needed<br>
      package update??? Where?<br>
      <br>
      And the page - <a moz-do-not-send="true"
        class="moz-txt-link-freetext"
        href="https://launchpad.net/ubuntu/trusty/+source/tidy">https://launchpad.net/ubuntu/trusty/+source/tidy</a>
      -<br>
      also shows 2009 Tidy, despite the fact that an update<br>
      (Ha!) was done 2015-07-23!!! Nearly a month after our<br>
      5.0.0 release...<br>
      <br>
      We certainly need to STIR something up somewhere ;=))<br>
      <br>
      Important Links:<br>
      <br>
          site: <a moz-do-not-send="true" class="moz-txt-link-freetext"
        href="http://www.html-tidy.org/">http://www.html-tidy.org/</a><br>
          source: <a moz-do-not-send="true"
        class="moz-txt-link-freetext"
        href="https://github.com/htacg/tidy-html5">https://github.com/htacg/tidy-html5</a><br>
          binaries: <a moz-do-not-send="true"
        class="moz-txt-link-freetext"
        href="http://www.htacg.org/binaries/">http://www.htacg.org/binaries/</a><br>
          bugs: <a moz-do-not-send="true" class="moz-txt-link-freetext"
        href="https://github.com/htacg/tidy-html5/issues">https://github.com/htacg/tidy-html5/issues</a><br>
          list: <a moz-do-not-send="true" class="moz-txt-link-freetext"
        href="https://lists.w3.org/Archives/Public/html-tidy/">https://lists.w3.org/Archives/Public/html-tidy/</a><br>
          api: <a moz-do-not-send="true" class="moz-txt-link-freetext"
        href="http://www.htacg.org/tidy-html5/tidylib_api/">http://www.htacg.org/tidy-html5/tidylib_api/</a><br>
          quickref: <a moz-do-not-send="true"
        class="moz-txt-link-freetext"
        href="http://www.htacg.org/tidy-html5/quickref.html">http://www.htacg.org/tidy-html5/quickref.html</a><br>
      <br>
      Regards,<br>
      Geoff.<br>
      <br>
      <br>
      <div class="moz-cite-prefix">On 26/09/15 01:41, Edward Vielmetti
        wrote:<br>
      </div>
      <blockquote
cite="mid:CAPRZce3DYpivPgRnOEdfn0eQA3jTC5jx3+KoaQf6kU=xuuWWSg@mail.gmail.com"
        type="cite">
        <div dir="ltr">Sierk - sure take my text and use it if it will
          help.
          <div><br>
          </div>
          <div>My next desire is not so much for Apple to update tidy
            (since it's readily</div>
          <div>available in Macports and fink and Homebrew that platform
            is OK).</div>
          <div>But Debian has an ancient tidy and I think that's
            addressable</div>
          <div>in finite time to improve at least to get tidy-html5 into
            `sid`.</div>
        </div>
        <div class="gmail_extra"><br>
          <div class="gmail_quote">On Fri, Sep 25, 2015 at 5:52 PM,
            Sierk Bornemann <span dir="ltr">&lt;<a
                moz-do-not-send="true" href="mailto:[email protected]"
                target="_blank"><a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a></a>&gt;</span> wrote:<br>
            <blockquote class="gmail_quote" style="margin:0 0 0
              .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi
              Geoff,<br>
              hi Edward,<br>
              hi Ryan!<br>
              <br>
              Tidy is part of Apple’s Open Source stack Darwin and so
              part of their OS X distribution since years [1] as well as
              part of iOS as well as of their newest OS, watchOS.
              Unfortunately, it's a very old version:<br>
              <br>
              OS X 10.10.5 (Yosemite)<br>
              $ tidy --version<br>
              HTML Tidy for Mac OS X released on 31 October 2006 - Apple
              Inc. build 15.15<br>
              <br>
              Latest security updates for iOS and watchOS contain
              updates for tidy, concerning CVE-2015-5522 and
              CVE-2015-5523 vulnerabilities, which are closed in Tidy
              4.9.31 and later 5.x.<br>
              <br>
              Apples Tidy is very outdated, is an old version based on
              the last available version on SourceForge, hasn’t changed
              and updated for years, isn’t capable of HTML5.<br>
              Years ago, Nov 17 2008, I filed a bug "Update HTML Tidy
              and TidyLib to the latest official version" in Apple’s
              internal bug database on <a moz-do-not-send="true"
                href="https://bugreport.apple.com/" rel="noreferrer"
                target="_blank">https://bugreport.apple.com/</a> and
              mirrored the bug for transparency purpose on OpenRadar
              [3]. I updated the bug’s information July 31 2014,
              reflecting that W3C had forked the dead SF tidy project to
              give it new life and to urge Apple to please update tidy.<br>
              So far no reaction, no update from Apple to their tidy.<br>
              Since then, I’ve not updated the bug’s description, to
              reflect the new situation under HTACG’s umbrella, but want
              do so shortly.<br>
              <br>
              [1] <a moz-do-not-send="true"
                href="http://www.opensource.apple.com/" rel="noreferrer"
                target="_blank">http://www.opensource.apple.com/</a><br>
              <a moz-do-not-send="true"
                href="http://www.opensource.apple.com/source/tidy/"
                rel="noreferrer" target="_blank">http://www.opensource.apple.com/source/tidy/</a><br>
              <a moz-do-not-send="true"
                href="http://www.apple.com/opensource/" rel="noreferrer"
                target="_blank">http://www.apple.com/opensource/</a><br>
              <br>
              [2] APPLE-SA-2015-09-16-1 iOS 9<br>
              <a moz-do-not-send="true"
href="http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html"
                rel="noreferrer" target="_blank">http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html</a><br>
              <br>
              tidy<br>
              Available for:  iPhone 4s and later,<br>
              iPod touch (5th generation) and later, iPad 2 and later<br>
              Impact:  Visiting a maliciously crafted website may lead
              to arbitrary<br>
              code execution<br>
              Description:  A memory corruption issue existed in Tidy.
              This issues<br>
              was addressed through improved memory handling.<br>
              CVE-ID<br>
              CVE-2015-5522 : Fernando Munoz of NULLGroup.com<br>
              CVE-2015-5523 : Fernando Munoz of NULLGroup.com<br>
              <br>
              APPLE-SA-2015-09-21-1 watchOS 2<br>
              <a moz-do-not-send="true"
href="http://lists.apple.com/archives/security-announce/2015/Sep/msg00005.html"
                rel="noreferrer" target="_blank">http://lists.apple.com/archives/security-announce/2015/Sep/msg00005.html</a><br>
              <br>
              [quote]<br>
              tidy<br>
              Available for:  Apple Watch Sport, Apple Watch,<br>
              and Apple Watch Edition<br>
              Impact:  Visiting a maliciously crafted website may lead
              to arbitrary<br>
              code execution<br>
              Description:  A memory corruption issue existed in Tidy.
              This issues<br>
              was addressed through improved memory handling.<br>
              CVE-ID<br>
              CVE-2015-5522 : Fernando Munoz of NULLGroup.com<br>
              CVE-2015-5523 : Fernando Munoz of NULLGroup.com<br>
              [/quote]<br>
              <br>
              [3] OpenRadar bug 6376494 (Apple internal rdar://6376494):
              Update HTML Tidy and TidyLib to the latest official
              version<br>
              <a moz-do-not-send="true"
                href="http://openradar.appspot.com/6376494"
                rel="noreferrer" target="_blank">http://openradar.appspot.com/6376494</a><br>
              <br>
              <br>
              <br>
              My question to you is: what can be done, what can you/we
              do, beyond my past efforts in this case, to convince Apple
              to eventually update its old outdated stock tidy to the
              most recent stable one of HTACG? Any Idea? Any
              suggestions?<br>
              <br>
              @Edward Vielmetti:<br>
              May I take, with your allowance, just for convenience and
              instead of writing my own text, your text of fink ticket
              #1044 <a moz-do-not-send="true"
                href="http://sourceforge.net/p/fink/package-requests/1044/"
                rel="noreferrer" target="_blank">http://sourceforge.net/p/fink/package-requests/1044/</a>
              and copy it for updating my Apple Rdar-bug 6376494 as well
              as its OpenRadar equivalent?<br>
              <br>
              Suggestions and help welcome,<br>
              Regards,<br>
              Sierk Bornemann<br>
              <br>
              --<br>
              Sierk Bornemann | web developer | germany<br>
              <br>
            </blockquote>
          </div>
          -- <br>
          <div class="gmail_signature">Edward Vielmetti +1 734 330 2465
            <div><a moz-do-not-send="true"
                href="mailto:[email protected]" target="_blank">[email protected]</a></div>
            <div><br>
            </div>
          </div>
        </div>
      </blockquote>
      <br>
      <br>
    </div>
    <br>
  </body>
</html>

--------------070606030407000503040301--